mirror of
https://gitlab.com/buildroot.org/buildroot.git
synced 2026-10-03 07:21:45 -09:00
Fixes a sandbox escape through symlink traversal tracked in
CVE-2026-87766, which affects all previous versions.
Using the bwrap binary with the setuid bit set is no longer supported
and user namespaces are now always required, so a kernel config fixup
is applied.
A new build option allows indicating the minimum kernel version that
will be used, which removes code used for backwards compatibility with
kernels older than 5.6.0 when a newer version is specified. Passing
$(LINUX_VERSION_PROBED) seems reasonable here.
This version also changed the license from LGPL-2.0+ to LGPL-2.1+,
hence the updated hash.
Release notes:
https://github.com/containers/bubblewrap/releases/tag/v0.12.0
Signed-off-by: Adrian Perez de Castro <aperez@igalia.com>
[Julien: fix _LINUX_CONFIG_FIXUPS by adding the missing "_LINUX"]
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 4cb6193d2e)
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
6 lines
317 B
Plaintext
6 lines
317 B
Plaintext
# From https://github.com/containers/bubblewrap/releases/download/v0.12.0/bubblewrap-0.12.0.tar.xz.sha256sum
|
|
sha256 9760d007363e3abba7c747489910f9f82d9fca53ba3bd3282e396fa3c97a3314 bubblewrap-0.12.0.tar.xz
|
|
|
|
# Hash for license files:
|
|
sha256 dc626520dcd53a22f727af3ee42c770e56c97a64fe3adb063799d8ab032fe551 COPYING
|